Courseiva
Security →mediumMultiple Select

XK0-006 Security Practice Question

A Linux administrator is hardening a server that runs a custom application. The security team requires that the system enforce password complexity and account lockout policies. The administrator decides to use PAM. Which TWO modules should be added to the appropriate PAM configuration files to enforce these requirements? (Choose two.)

⚠ Common exam trap

The trap here is selecting the deprecated pam_tally2.so for lockout instead of the current pam_faillock.so, which is now the recommended module on modern Linux distributions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

pam_faillock.so

To enforce password complexity, pam_pwquality.so is the standard module, checking password strength against configured criteria. For account lockout, pam_faillock.so is the modern replacement for pam_tally2.so, tracking failed attempts and locking accounts after a threshold. Together, they meet the security team's requirements when placed in the correct PAM stacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    pam_unix.so

    Why it's wrong here

    pam_unix.so handles traditional Unix password authentication and shadow password updates. It does not enforce complexity rules or lockout policies by itself. While it is a core module for authentication, it cannot fulfill the specific requirements of complexity and lockout without additional modules.

  • ✓

    pam_faillock.so

    Why this is correct

    pam_faillock.so provides account lockout after a specified number of failed authentication attempts. It is configured in the auth and account stacks of PAM configuration files, such as /etc/pam.d/system-auth and /etc/pam.d/password-auth. This module satisfies the account lockout requirement and is the current standard on Red Hat and similar distributions.

  • ✗

    pam_tally2.so

    Why it's wrong here

    pam_tally2.so is a legacy module for counting failed login attempts and locking accounts. While it can enforce lockout policies, it has been deprecated in favor of pam_faillock.so on modern distributions. Using it may work but is not the recommended current module, and it does not handle password complexity.

  • ✗

    pam_limits.so

    Why it's wrong here

    pam_limits.so sets resource limits for user sessions, such as maximum number of processes or open files. It does not deal with password complexity or account lockout. It is used in the session stack and is unrelated to the security requirements described.

  • ✓

    pam_pwquality.so

    Why this is correct

    pam_pwquality.so enforces password quality rules such as minimum length, character classes, and dictionary checks. It is typically placed in the password stack of /etc/pam.d/common-password or /etc/pam.d/system-auth. This module directly addresses the password complexity requirement by rejecting weak passwords during password changes.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.